GitLab team
25 exploits
Active since Aug 2020
GitLab <13.0.12-13.2.3 - Memory Corruption
CVSS 6.5
GitLab Runner < 13.1.3, 13.2.3, 13.3.1 - Denial of Service via Malformed Queries
CVSS 6.5
Gitlab <13.4.7, <13.5.5, <13.6.2 - DoS
CVSS 4.3
GitLab 12.4.0-13.5.5 - Denial of Service via Malicious Package Name Input
CVSS 4.3
GitLab 8.4.0-13.4.6 13.5.0-13.5.4 13.6.0-13.6.1 - Information Disclosure in Advanced Search
CVSS 4.0
GitLab 13.7.0-13.7.1 - Denial of Service via Malformed HTTP Method
CVSS 5.3
GitLab 11.6.0-13.5.5 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.2
GitLab 13.11.0-13.11.4 - Information Disclosure via On-Call Rotation Data
CVSS 7.5
GitLab 14.1.1-14.1.6 - Two-Factor Authentication Bypass via Basic Authentication
CVSS 3.1
GitLab 10.8.0-14.1.6 - Information Disclosure via SendEntry Rails Log Exposure
CVSS 2.0
GitLab 11.0-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Denial of Service via Diff Feature
CVSS 4.3
GitLab < 14.3.6, 14.4-14.4.4, 14.5-14.5.2 - Improper Privilege Management via Access Memoization Collision
CVSS 5.9
GitLab 8.15.0-14.3.5, 14.4.0-14.4.3, 14.5.0-14.5.1 - Denial of Service via Deploy Slash Command Regex
CVSS 3.1
GitLab Runner 13.7-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Uncontrolled Resource Consumption via Crafted Docker Image
CVSS 6.5
GitLab Runner <14.5.2 - Buffer Overflow
CVSS 5.3
GitLab 12.10-14.4.4, 14.5.0-14.5.2, 14.6.0-14.6.1 - Denial of Service via Package Deletion Request
CVSS 6.5
GitLab <14.4.5-14.6.2 - Info Disclosure
CVSS 6.5
GitLab CE/EE <12.3 - Info Disclosure
CVSS 5.3
GitLab 7.9-14.7.1 - Server-Side Request Forgery via Irker DNS Rebinding
CVSS 5.4
GitLab <14.5.4, <14.6.4, <14.7.1 - DoS
CVSS 4.9
GitLab 1.0.2-14.8.5, 14.9.0-14.9.3, 14.10.0 - Insufficiently Protected Credentials via Integration Properties
CVSS 5.4
GitLab CE/EE <14.9.5-15.0.1 - Info Disclosure
CVSS 4.3
GitLab EE 12.0-14.9.4, 14.10-14.10.3, 15.0 - Incorrect Authorization via Project Trigger Token Bypass
CVSS 6.5
GitLab CE/EE <14.9.5-15.0.1 - Privilege Escalation
CVSS 5.4
GitLab <15.1.6-15.3.2 - Auth Bypass
CVSS 6.5